From d5e52d7d001dab73bd3137b641aa4ac89bba3f2b Mon Sep 17 00:00:00 2001 From: Benson Wong Date: Sat, 14 Feb 2026 10:23:08 -0800 Subject: [PATCH] build: disable provenance attestations in container builds (#523) ## Summary - Add `--provenance=false` to docker build commands in `build-container.sh` - BuildKit attestation manifests are stored as untagged images in GHCR, and the `delete-untagged-containers` cleanup job deletes them, breaking the manifest list and causing `manifest unknown` errors on pull - ref: https://github.com/actions/delete-package-versions/issues/162 --- docker/build-container.sh | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/docker/build-container.sh b/docker/build-container.sh index 19b96b3e..b1f3c184 100755 --- a/docker/build-container.sh +++ b/docker/build-container.sh @@ -142,7 +142,7 @@ for CONTAINER_TYPE in non-root root; do fi log_info "Building $CONTAINER_TYPE $CONTAINER_TAG $LS_VER" - docker build -f llama-swap.Containerfile --build-arg BASE_TAG=${BASE_TAG} --build-arg LS_VER=${LS_VER} --build-arg UID=${USER_UID} \ + docker build --provenance=false -f llama-swap.Containerfile --build-arg BASE_TAG=${BASE_TAG} --build-arg LS_VER=${LS_VER} --build-arg UID=${USER_UID} \ --build-arg LS_REPO=${LS_REPO} --build-arg GID=${USER_GID} --build-arg USER_HOME=${USER_HOME} -t ${CONTAINER_TAG} -t ${CONTAINER_LATEST} \ --build-arg BASE_IMAGE=${BASE_IMAGE} . @@ -150,7 +150,7 @@ for CONTAINER_TYPE in non-root root; do case "$ARCH" in "musa" | "vulkan") log_info "Adding sd-server to $CONTAINER_TAG" - docker build -f llama-swap-sd.Containerfile \ + docker build --provenance=false -f llama-swap-sd.Containerfile \ --build-arg BASE=${CONTAINER_TAG} \ --build-arg SD_IMAGE=${SD_IMAGE} --build-arg SD_TAG=${SD_TAG} \ --build-arg UID=${USER_UID} --build-arg GID=${USER_GID} \